LWA-2026-11401 confirmed malware

space-items@1.0.0

Malicious code in space-items (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1057 · Process DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071 · Application Layer ProtocolT1105 · Ingress Tool TransferT1573 · Encrypted ChannelT1041 · Exfiltration Over C2 ChannelT1547.001 · Registry Run Keys / Startup FolderT1053.003 · CronT1543 · Create or Modify System ProcessT1046 · Network Service DiscoveryT1135 · Network Share DiscoveryT1572 · Protocol Tunneling

Analysis

The postinstall hook (scripts/bootstrap.js) executes a multi-stage implant on install. It enumerates sandbox-escape conditions (capabilities, cgroup, mounts, docker/containerd sockets, Kubernetes serviceaccount token, /proc/1/root), then harvests credentials from /run/secrets/zti, ~/.aws, ~/.ssh, /etc/ssl/private, ~/.npmrc, ~/.gitconfig, and /proc/1/environ (filtering for key/token/secret/pass). It establishes a reverse beacon to 159[.]75[.]160[.]206:4444 (with reconnect watchdog) that supports remote command execution, reverse TCP tunneling, and arbitrary file reads. It installs persistence by writing .beacon.js into the project root, rewriting the project's package.json scripts (prepare/prebuild/prelint) to re-run the beacon on every build, adding cron entries and /etc/cron.d/beacon, appending a hook to /root/.bashrc, and spawning a detached setsid watchdog. It also performs an internal network scan of 10[.]100[.]0[.]46, 10[.]201[.]0[.]1, 10[.]100[.]16[.]43, 10[.]100[.]67[.]1, 10[.]100[.]67[.]124 across ports 80/443/5432/5433/8080/8443/3000/3001/9090/6379/2379/6443/10250/22, and brute-forces MCP routes on 10[.]100[.]0[.]46 (Host: mcp[.]miaoda[.]cn) using MIAODA_SANDBOX_MCP_AUTHORIZATION_KEY / INTEGRATIONS_API_KEY from the environment. Probe output is written to rt3-probe.log / sysinfo3.log and beacon status to /tmp/beacon3.status.

analyzed by
Leitwacht
first seen
Aug 17, 2026, 03:56 PM
analyzed
Aug 17, 2026, 03:56 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.